Skip to main content
    Pritect
    All resources
    CybersecurityCapability deep-dive9 min readUpdated 30 Jun 2026

    Maturity assessments and gap analysis: how to actually raise your security and data protection posture

    A practical guide to using maturity assessments, target setting, and gap analysis to move data protection and cybersecurity from ad hoc to managed, with the improvement loop that makes it stick.

    By André Årnes and Magdalena Goralczyk

    Most organisations know roughly where their weak spots are. What they struggle with is turning that hunch into a defensible, measurable programme of improvement that a board, an auditor, or a regulator will accept. A maturity assessment is how you replace "we think we're reasonably good at access control" with "we are at Level 2, our target is Level 3, and here is the dated plan to close the gap."

    This guide walks through the full loop: assess where you are, set where you want to be, measure the gap, and close it. It applies to both cybersecurity and data protection, and it is the backbone of how Pritect helps teams improve rather than just record.

    Why a maturity model beats a checklist

    A checklist answers a binary question: is the control present or not. That is useful for a point-in-time audit, but it tells you nothing about how well something is done, and it gives you nowhere to go once every box is ticked.

    A maturity model answers a better question: how consistently, how measurably, and how durably is this control operating. That turns governance into something you can improve year over year, and it matches how supervisory authorities and frameworks increasingly think, from NIS2's risk-management expectations to the ICO's Accountability Framework.

    The maturity scale

    Pritect scores cybersecurity controls on a six-point scale, from 0 to 5. Each level has a clear, evidence-based definition so two different assessors reach the same score.

    LevelNameWhat it means
    0Not ImplementedNo control in place, or no evidence one exists
    1Ad HocInitial or informal effort, little documentation
    2DevelopingDocumented intent, but inconsistent execution
    3DefinedA repeatable process with evidence of consistent execution
    4ManagedMeasured and managed, with coverage reporting
    5OptimisedContinuously improved, with independent assurance

    Level 3 (Defined) is the sensible default target for most controls: a documented, repeatable process that actually runs. Levels 4 and 5 are where you invest selectively, on the controls that matter most to your risk profile.

    What gets assessed

    For cybersecurity, the assessment is built on the Pritect Cybersecurity Framework, which organises 100+ controls into 16 domains, including governance and compliance, identity and access management, asset management, cryptography, monitoring and detection, incident management, supply chain, and AI security. For data protection, the same maturity approach aligns to the ICO Accountability Framework's domains.

    The point of the domain structure is that you do not get one blurry overall number. You get a profile: strong on identity, weak on supply chain, average on monitoring. That profile is what makes the gap analysis actionable.

    Three ways to assess, depending on how much rigour you need

    Not every assessment needs to be audit-grade. Pritect offers three modes so the effort matches the purpose:

    • Self-assessment: a quick baseline. No evidence required, no approver. Good for a first read or an internal pulse check.
    • Evidence-based: evidence uploads are encouraged against each answer, but not blocking. The right level for an ongoing internal programme.
    • Auditable: evidence is mandatory per control and an assigned approver signs the assessment off. This is the mode you run when the result has to stand up to an external auditor or regulator.

    Setting a target

    A score on its own is just a measurement. It becomes a goal when you set a target. In Pritect you set an overall target maturity (Level 3 by default) and then override it per domain, because your ambition for identity and access management is probably higher than for, say, on-premise management if you are mostly cloud.

    Targets are versioned and run through an approval workflow, with a rationale recorded against each one. That matters because the target is a governance decision: leadership is agreeing what "good enough" means for this organisation, this year.

    Gap analysis: the distance between now and the goal

    Once you have a completed baseline assessment and a target, the gap is straightforward arithmetic done per domain:

    Gap = target level − current score

    Pritect bands the result so attention goes where it is needed:

    BandGap sizeReading
    On target0 or belowCurrent maturity meets or exceeds the target
    Minorup to 0.5Close; a small push gets there
    Moderate0.5 to 1.0A real gap worth a planned initiative
    Significantabove 1.0Priority; likely needs dedicated effort and budget

    The output is a domain-by-domain view with the baseline score, the target, the gap, and its severity, plus summary statistics: your average gap, how many domains are on target, and how many sit in each band. Domains you mark Not Applicable are excluded from the averages rather than dragging your numbers down with phantom gaps.

    Closing gaps is a programme, not a paragraph

    The most common failure mode is a beautiful gap report that nobody acts on. Pritect treats each gap as the start of a tracked remediation action: a titled initiative with a priority, an owner, start and end dates, and the specific controls it addresses. Each action records its expected impact, for example lifting governance from 2.5 to 3.2, so you can forecast the maturity you will reach before you spend the effort.

    The improvement loop

    Put together, the four steps form a loop you run on a cadence, not once:

    1. Assess the current state, control by control, at the rigour level you need.
    2. Set or confirm the target, overall and per domain.
    3. Analyse the gaps, prioritising by severity and risk.
    4. Close the gaps through owned, dated actions, then re-assess.

    Each turn of the loop produces a new baseline, so over two or three cycles you have something more valuable than any single score: a trend. "Our average gap fell from 1.3 to 0.4 over the year, and every Tier 1 domain is now at or above target" is a sentence a board understands and an auditor respects.

    Reporting that lands

    Because every score, target, and action lives on the same record, the reporting comes for free. Pritect generates board-ready maturity and gap reports: baseline versus target per domain, the priority areas, the remediation status, and the trend over time. The same data feeds the executive dashboards, so security and data protection maturity sit alongside the rest of your governance posture in one view, rather than in a slide someone rebuilt by hand the night before.

    See the maturity model, target setting, and gap analysis in the Pritect cybersecurity suite.

    Explore Cybersecurity

    The same maturity and gap approach runs in the data protection suite against the ICO Accountability Framework, so you can hold privacy and security to the same measurable standard.

    Run the same maturity and gap loop across your data protection programme.

    Explore Data Protection